# IP Intelligence Briefing: 111.26.62.46/32
## Executive Summary
IP address 111.26.62.46 is classified as High Risk (80/100) and operates within China Mobile Group Jilin Communications Corporation's infrastructure. The IP shows elevated threat characteristics with DNSBL listings on 6 of 8 total lists and is associated with a subnet exhibiting 1.0 abuse density. Immediate monitoring and blocking recommendations are warranted.
## Ownership and Infrastructure
- ASN: AS134810 - IRT-CHINAMOBILE-CN
- Organization: China Mobile Group Jilin Communications Corporation
- Network Type: Mobile Carrier
- Geolocation: Changchun, Jilin Province (CN)
- BGP Prefix: 111.26.48.0/20
- Classification: Firewalled / No Services
## Threat Indicators
- Risk Score: 80 (High Risk)
- DNSBL Listings: 6 of 8 total lists
- Reputation: High Risk
- Not classified as: Known attacker, spam source, Tor exit node, or hosting provider
- Operator Score: 0.1304 (Minimal)
The IP demonstrates threat indicators despite lacking traditional attacker signatures. Multiple pulse sources have flagged the address, though specific campaign associations remain unconfirmed.
## Network Neighborhood Analysis
The /24 subnet (111.26.62.46/24) shows concerning abuse patterns:
- Abuse Density: 1.0 (Maximum)
- Threat Siblings: 3 out of 4 IPs flagged as high risk
- High-Risk Neighbors: 111.26.62.37, 111.26.62.39, 111.26.62.42 (all scored 80/100)
- Classification: Mostly clean (despite neighborhood density)
The neighborhood exhibits concentrated risk, suggesting potential coordinated activity or shared infrastructure abuse.
## Historical Observations
Analysis of 19 observations reveals:
- Most Recent: June 22, 2026 with threat signals and ASN-level reputation data
- Threat Persistence: Multiple pulse sources active
- Stability: Route stability flagged as false
- Observation Trend: Consistent threat signaling over monitoring period
## Network Relationships
Fifteen relationships identified, all classified as "Same Network" with CMNET network designation, indicating extensive China Mobile infrastructure associations.
## Recommended Security Actions
Immediate Actions
Monitoring:
- Increase logging verbosity and review recent activity from this IP
- Severity: Critical (Risk Score 80/100)
Blocking Rules:
iptables:
```
iptables -A INPUT -s 111.26.62.46 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 111.26.62.46 drop
```
nginx:
```
deny 111.26.62.46;
```
pfSense:
```
111.26.62.46/32
```
Cloudflare WAF:
```json
{
"description": "Block 111.26.62.46 โ IPDebrief risk score 80",
"action": "block",
"filter": {"expression": "ip.src eq 111.26.62.46"}
}
```
AWS WAF:
```json
{
"Addresses": ["111.26.62.46/32"],
"Description": "IPDebrief risk 80"
}
```
## Analysis Notes
The IP represents a mobile carrier address with elevated threat indicators. While not classified as a known attacker, the combination of high risk score, DNSBL listings, and neighborhood abuse density suggests potential malicious activity. The subnet's 1.0 abuse density with three high-risk siblings indicates systematic risk requiring defensive posture. SOC analysts should correlate with other threat intelligence sources before implementing permanent blocks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-CHINAMOBILE-CN |
| ASN | AS134810 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 19% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:30 UTC |
| Last Seen | 2026-06-26 08:22:58 UTC |
| Profile Built | 2026-06-22 09:09:23 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 20 |
Full dossier details are available via our API.